Man-in-the-middle attack in IBM Corporation products - CVE-2018-1454

 

Man-in-the-middle attack in IBM Corporation products - CVE-2018-1454

Published: June 5, 2018


Vulnerability identifier: #VU13184
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1454
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct man-in-the-middle attack.

The vulnerability exists due to system does not properly enable HTTP Strict Transport Security. A remote attacker can conduct man-in-the-middle attack, intercept of the communication channel between the affected app and access arbitrary data.


Affected software

IBM InfoSphere Information Governance Catalog
IBM InfoSphere Data Click
IBM InfoSphere Information Server for Cloud

How to mitigate CVE-2018-1454

Install update from vendor's website.


External References

Related Security Bulletins